CVE-2008-5931
Estado: ModificadaMedia (5)—
The Net Guys ASPired2Blog stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the database file containing usernames and passwords via a direct request for admin/blog.mdb. NOTE: some of these details are obtained from third party information.
CVSS
- Versión: 2.0
- Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N
- Puntuación base: 5
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 2.62%
- Percentil entre todas las CVEs puntuadas: 85
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
CWE
- CWE-264
Referencias
- http://secunia.com/advisories/33134
- http://securityreason.com/securityalert/4931
- https://exchange.xforce.ibmcloud.com/vulnerabilities/47294
- https://www.exploit-db.com/exploits/7436
- http://secunia.com/advisories/33134
- http://securityreason.com/securityalert/4931
- https://exchange.xforce.ibmcloud.com/vulnerabilities/47294
- https://www.exploit-db.com/exploits/7436
JSON original (NVD)
Mostrar
{
"id": "CVE-2008-5931",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 5,
"accessVector": "NETWORK",
"vectorString": "AV:N/AC:L/Au:N/C:P/I:N/A:N",
"authentication": "NONE",
"integrityImpact": "NONE",
"accessComplexity": "LOW",
"availabilityImpact": "NONE",
"confidentialityImpact": "PARTIAL"
},
"acInsufInfo": false,
"impactScore": 2.9,
"baseSeverity": "MEDIUM",
"obtainAllPrivilege": false,
"exploitabilityScore": 10,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
]
},
"affected": [
{
"source": "cve@mitre.org",
"affectedData": [
{
"vendor": "n/a",
"product": "n/a",
"versions": [
{
"status": "affected",
"version": "n/a"
}
]
}
]
}
],
"published": "2009-01-21T18:30:00.517",
"references": [
{
"url": "http://secunia.com/advisories/33134",
"tags": [
"Vendor Advisory"
],
"source": "cve@mitre.org"
},
{
"url": "http://securityreason.com/securityalert/4931",
"source": "cve@mitre.org"
},
{
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/47294",
"source": "cve@mitre.org"
},
{
"url": "https://www.exploit-db.com/exploits/7436",
"source": "cve@mitre.org"
},
{
"url": "http://secunia.com/advisories/33134",
"tags": [
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://securityreason.com/securityalert/4931",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/47294",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://www.exploit-db.com/exploits/7436",
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-264"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "The Net Guys ASPired2Blog stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the database file containing usernames and passwords via a direct request for admin/blog.mdb. NOTE: some of these details are obtained from third party information."
},
{
"lang": "es",
"value": "The Net Guys ASPired2Blog almacena información sensible en la raíz web con un control de acceso insuficiente, lo que permite a atacantes remotos descargar el archivo de la base de datos conteniendo nombre de usuarios y contraseñas mediante una petición directa de admin/blog.mdb. NOTA: alguno de estos detalles se han obtenido de información de terceros."
}
],
"lastModified": "2026-06-16T23:01:15.287",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:the_net_guys:aspired2blog:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "267E0FF1-3B27-430C-969F-14B13B2D19D9"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "cve@mitre.org"
}